Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Bug Bounty Programs – The Good and the Bad
News & Analysis

Bug Bounty Programs – The Good and the Bad

ISBuzz TeamBy ISBuzz TeamSeptember 23, 2014Updated:May 2, 20256 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
bug_bounty
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Bug bounties are in the news again. Twitter has announced its own program[1], while Robert Graham of Errata Security has argued that legal actions brought for loss of personal data will more than likely succeed against any company if the service provider does not have a bounty program[2]. He reasons this is so because in the absence of a bug bounty program, it would appear that a breached company did not do all it could to prevent the intrusion.

FREE Webinar: Learn How to Stop Targeted Attacks and Avoid “Expense In Depth” With Strong Authentication

Graham’s point of view implies that bug bounties are an effective security process. Twitter’s bounties suggest they need not be expensive. But are these true? I spoke to Ilia Kolochenko, CEO and founder of High-Tech Bridge, a firm that specializes in penetration testing and vulnerability discovery.

“Bug bounties,” he said, “can be an extremely effective tool if they are implemented and operated correctly. The problem, however, is that this is difficult to do and rarely achieved, and they can actually do more harm than good.”

The main problem is that once a bounty program is in place, hackers consider it a green light to attack the system. Those who attack are frequently hackers who have very limited experience with professional security testing–actors who can actually damage the system they are probing. “Checking for XSS is harmless and even without a bounty program I would say perfectly legal if the investigation is used to notify the vendor,” said Kolochenko. “But in checking for something more dangerous, like SQLi flaws, if the researcher is not skilled enough, he could unintentionally delete something or make something unusable by incompetent testing. I am not even speaking about automated tools and scanners that can seriously harm live systems if used blindly. The problem is that quite often crowds of young hackers use a dozen vulnerability scanners simultaneously to fuzz the victim. They bet on the quantity rather than quality of security checks.”

In many jurisdictions, SQLi probing could be considered illegal. The presence of a bounty program, however, removes this restriction even for low-calibre hackers. High-level researchers, added Kolochenko, don’t usually care about bug bounties. “Competent researchers are not usually the people who regularly submit bugs to collect the bounties, simply because that is not their motivation. They may do it from time to time for glory or mainly for fun/challenge, but that’s definitely not their core business/hobby.”

But if we have a situation where the existence of a bounty scheme has intrinsic dangers, this is often exacerbated by the bounty itself. Consider the starting point for Twitter’s program: $140. “It’s almost an insult,” said Kolochenko. “Personally I don’t know any professional security researcher who would be interested in digging into Twitter systems for $140 – in fact I don’t know anyone who would systematically do it for $1400 – Twitter is not a small self-written CMS. Its audit requires serious experience, qualification and plenty of time. And time is money. Obviously, people [who submit vulnerabilities to Twitter these days] may be motivated by glory and challenge, but such motivation usually disappears quite quickly.”

In fact, Twitter isn’t even the worst culprit. Hackerone Inc coordinates numerous bounty schemes for many companies; and a quick glance through its Public Programs page[3] shows a large number of very small bounties. While OpenSSL offers a minimum bounty of $2500 and Sandbox Escape offers $5000, Yahoo offers a pitiful $50. Even this, however, is an improvement. You may recall that almost exactly a year ago Kolochenko found and reported four XSS on Yahoo[4]. His reward was a $12.50 discount voucher to be spent in the Yahoo Store – in other words, a tee-shirt with Yahoo’s logo. The public outcry was so great that Yahoo rapidly evolved a new scheme, which it said at the time would start at $150. It seems to have had second thoughts and dropped this to just $50.

Is the solution simply to offer greater rewards in order to attract more serious researchers? Partly, says Kolochenko – but another issue is the way the schemes are implemented. “The problem is companies think that bug bounties are simply something they can announce and that will be enough.” Management often thinks it’s a good idea that can be handled by IT without any further resources (other than the bounty itself).

This is not the case, says Kolochenko –efficient bug bounty actually requires a dedicated team to handle it effectively. It’s those unexperienced beginners and enthusiasts again. “They’re not always very good at explaining the vulnerability, often just submitting a screen-shot or a raw HTTP request as the only explication and/or proof. The company then has to spend hours trying to work out what they’re trying to say – is it a vulnerability, a weakness, a feature; a false-positive; a third-party software vulnerability; etc.”

An under-resourced bounty team can easily become overloaded and not reply. The danger here, suggests Kolochenko, is that the researcher is easily offended. “OK, if you’re not interested in what we’ve discovered, we’ll swap our white hat for a grey/black hat and talk to someone else who may well pay us more.” So once again, a poorly implemented bounty scheme might end up causing more harm than it prevents. Moreover, one should not forget that a bug-bounty, even properly implemented, can never replace professional information security services and solutions, but just complete them.

Does this mean, then, that bug bounty schemes should be abandoned?

“Not at all,” said Kolochenko. “A well-resourced and implemented bug bounty scheme can be very useful. But it should be considered as part of the company’s overall security posture and planned, implemented and resourced as such.” It is not something that can just be announced and expected to work, but something that offers sufficient rewards (not only financial ones) to attract top-grade researchers. For example, a job offer for the top researcher of the year would be a great motivator for many talented people from developing countries, as well as great benefit to the corporate security. Companies should also clearly understand and keep in mind that bug bounty requires quite serious financial investment, and a team to handle all the submissions. With all of this in place, says Kolochenko, the bug bounty scheme becomes an additional, very useful security layer for the service provider.

References

[1] https://hackerone.com/twitter

[2]

[3]

[4] http://www.infosecurity-magazine.com/news/yahoo-offers-1250-as-bug-bounty/

About High-Tech Bridge

High-Tech BridgeHeadquartered in Geneva, Switzerland, High-Tech Bridge provides customers in Europe, the United States, the Middle East and across the globe with information security services such as penetration testing, security auditing, computer crime investigation and web application security testing.

In 2012, analyst firm Frost & Sullivan recognised High-Tech Bridge as one of the market leading service providers in the ethical hacking industry. High-Tech Bridge also received the prestigious Online Trust Alliance Honor Roll award in 2012, 2013 and 2014.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

AppSec is dead, long live AI security

April 29, 20265 Mins Read

Managing App Access on Frontline Devices in an Always-On World

March 9, 20264 Mins Read

OWASP Top 10 2025: New Enemies, Old Foes, and an Approach to Vulnerability Remediation That Must Evolve

January 22, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}